On Wed, 06 Feb 2008 03:59:30 PST, coderman said:
> since psk without key distribution nor secure secret exchange does not
> solve the problems that HTTPS solves, to say this is useful in
> situations where HTTPS is not available is disingenuous.
Sure. So you e-mail the shared secret in a PGP or S/MIME encrypted mail.
So saying that it doesn't work because there's no secure secret exchange
is disingenuous as well.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- application/pgp-signature attachment: stored
Received on Feb 06 2008